LIVE DATA

Recent Data Breaches

967+ known breaches tracked. See if your accounts are affected.

967

Total Breaches

17.5B

Accounts Compromised

Mar 25, 2026

Most Recent Breach

925

Verified Breaches

Showing 20 of 967 breaches

BreachForums Version 5

breachforums.bf
Verified
Mar 25, 2026339.8K accounts
Email addressesPasswordsUsernames

In March 2026, a breach of one of the many iterations of the BreachForums hacking forum known as "Version 5" was publicly disclosed. The incident exposed 340k unique email addresses along with usernames and argon2 password hashes.

Check if you're affected

Sound Radix

soundradix.com
Verified
Mar 24, 2026293K accounts
Email addressesNamesPasswords

In March 2026, the audio production tools company Sound Radix disclosed a data breach that they subsequently self-submitted to HIBP. The incident impacted 293k unique email addresses and names. Sound Radix advised that it is possible that additional data including hashed passwords may have been exposed, and that no financial or credit card information was impacted.

Check if you're affected

Divine Skins

divineskins.gg
Verified
Mar 12, 2026105.8K accounts
Email addressesPurchasesUsernames

In March 2026, the League of Legends custom skins service Divine Skins suffered a data breach. The incident was disclosed via the service's Discord server, where Divine Skins stated that an unauthorised third party accessed part of its systems, deleted all skins from the database and exposed email addresses and usernames. The data also contained a history of purchases made by users.

Check if you're affected

Baydöner

baydoner.com
Verified
Mar 7, 20261.3M accounts
Dates of birthEmail addressesGendersGeographic locationsGovernment issued IDsNames+3 more

In March 2026, the Turkish restaurant chain Baydöner suffered a data breach which was subsequently published to a public hacking forum. The incident exposed over 1.2M unique email addresses along with names, phone numbers, cities of residence and plaintext passwords. A small number of records also included Turkish national ID number and date of birth. In their disclosure notice, Baydöner stated that payment and financial data was not affected.

Check if you're affected
Verified
Mar 5, 2026903.1K accounts
Customer service commentsEmail addressesIP addressesNamesPhone numbersPhysical addresses

In March 2026, the online safety service Aura disclosed a data breach that exposed 900k unique email addresses. The data was primarily associated with a marketing tool from a previously acquired company, with fewer than 20k active Aura customers affected. Exposed data included names, phone numbers, physical and IP addresses, and customer service notes. Aura advised that no Social Security numbers, passwords or financial information were compromised.

Check if you're affected

KomikoAI

komiko.app
Verified
Feb 24, 20261.1M accounts
AI promptsEmail addressesForum postsNames

In February, the AI-powered comic generation platform KomikoAI suffered a data breach. The incident exposed 1M unique email addresses along with names, user posts and the AI prompts used to generate content. The exposed data enables the mapping of individual AI prompts to specific email addresses.

Check if you're affected

Lovora

Verified
Feb 24, 2026495.6K accounts
Display namesEmail addressesProfile photos

In February 2026, the couples and relationship app Lovora allegedly suffered a data breach that exposed 496k unique email addresses. The data also included users’ display names and profile photos, along with other personal information collected through use of the app. The app’s maker, Plantake, did not respond to multiple attempts to contact them about the incident.

Check if you're affected
Verified
Feb 16, 202622.9K accounts
Email addressesPartial dates of birthUsernames

In February 2026, the porn addiction app Quitbro allegedly suffered a data breach that exposed 23k unique email addresses. The data also included users’ years of birth, responses to questions within the app and their last recorded relapse time. The app’s maker, Plantake, did not respond to multiple attempts to contact them about the incident.

Check if you're affected

CarGurus

cargurus.com
Verified
Feb 13, 202612.5M accounts
Email addressesIP addressesNamesPhone numbersPhysical addresses

In February 2026, the automotive marketplace CarGurus was the target of a data breach attributed to the threat actor ShinyHunters. Following an attempted extortion, the data was published publicly and contained more than 12M email addresses across multiple files including user account ID mappings, finance pre-qualification application data and dealer account and subscription information. Impacted data also included names, phone numbers, physical and IP addresses, and auto finance application outcomes.

Check if you're affected
Verified
Feb 11, 20266.1M accounts
Bank account numbersCustomer service commentsDates of birthDriver's licensesEmail addressesGenders+5 more

In February 2026, Dutch telco Odido was the victim of a data breach and subsequent extortion attempt. Shortly after, a total of 6M unique email addresses were published across four separate data releases over consecutive days. The exposed data includes names, physical addresses, phone numbers, bank account numbers, dates of birth, customer service notes and passport, driver’s licence and European national ID numbers. Odido has published a disclosure notice including an FAQ to support affected customers.

Check if you're affected

Toy Battles

toybattles.net
Verified
Feb 5, 20261K accounts
Chat logsEmail addressesIP addressesUsernames

In February 2026, the online gaming community Toy Battles suffered a data breach. The incident exposed 1k unique email addresses alongside usernames, IP addresses and chat logs. Following the breach, Toy Battles self-submitted the data to Have I Been Pwned.

Check if you're affected

Association Nationale des Premiers Secours

anps.fr
Verified
Jan 29, 20265.6K accounts
Dates of birthEmail addressesNamesPlaces of birthSalutations

In January 2026, a data breach impacting the French non-profit Association Nationale des Premiers Secours (ANPS) was posted to a hacking forum. The breach exposed 5.6k unique email addresses along with names, dates of birth and places of birth. ANPS self-submitted the data to HIBP and advised the incident was traced back to a legacy system and did not impact health data, financial information or passwords.

Check if you're affected

Provecho

provecho.bio
Verified
Jan 29, 2026712.9K accounts
Email addressesUsernames

In early 2026, data purportedly sourced from the recipe and meal planning service Provecho was alleged to have been obtained in a breach. The exposed data included 713k unique email address along with username and the creator account holders followed. Provecho has been notified and is aware of the claims surrounding the incident.

Check if you're affected
Verified
Jan 27, 2026967.2K accounts
Dates of birthEmail addressesNamesPhone numbersPhysical addresses

In February 2026, data obtained from the fintech lending platform Figure was publicly posted online. The exposed data, dating back to January 2026, contained over 900k unique email addresses along with names, phone numbers, physical addresses and dates of birth. Figure confirmed the incident and attributed it to a social engineering attack in which an employee was tricked into providing access.

Check if you're affected
Verified
Jan 23, 2026431.4K accounts
Email addressesNamesPhone numbersPhysical addresses

In January 2026, data allegedly sourced from US automotive retailer CarMax was published online following a failed extortion attempt. The data included 431k unique email addresses along with names, phone numbers and physical addresses.

Check if you're affected

Betterment

betterment.com
Verified
Jan 8, 20261.4M accounts
Dates of birthDevice informationEmail addressesEmployersGeographic locationsJob titles+3 more

In January 2026, the automated investment platform Betterment confirmed it had suffered a data breach attributed to a social engineering attack. As part of the incident, Betterment customers received fraudulent crypto-related messages promising high returns if funds were sent to an attacker-controlled cryptocurrency wallet. The breach exposed 1.4M unique email addresses, along with names and geographic location data. A subset of records also included dates of birth, phone numbers, and physical addresses. In its disclosure notice, Betterment stated that the incident did not provide attackers with access to customer accounts and did not expose passwords or other login credentials.

Check if you're affected

Instagram

instagram.com
Verified
Jan 6, 20266.2M accounts
Display namesEmail addressesGeographic locationsPhone numbersUsernames

In January 2026, data allegedly scraped via an Instagram API was posted to a popular hacking forum. The dataset contained 17M rows of public Instagram information, including usernames, display names, account IDs, and in some cases, geolocation data. Of these records, 6.2M included an associated email address, and some also contained a phone number. The scraped data appears to be unrelated to password reset requests initiated on the platform, despite coinciding in timeframe. There is no evidence that passwords or other sensitive data were compromised.

Check if you're affected

Panera Bread

panerabread.com
Verified
Jan 6, 20265.1M accounts
Email addressesNamesPhone numbersPhysical addresses

In January 2026, Panera Bread suffered a data breach that exposed 14M records. After an attempted extortion failed, the attackers published the data publicly, which included 5.1M unique email addresses along with associated account information such as names, phone numbers and physical addresses. Panera Bread subsequently confirmed that "the data involved is contact information" and that authorities were notified.

Check if you're affected

WhiteDate

whitedate.net
Verified
Dec 28, 202520.4K accounts
AgesAstrological signsBiosDevice informationEducation levelsEmail addresses+16 more

In December 2025, the dating website "for a Europid vision" WhiteDate suffered a data breach that was subsequently leaked online, initially exposing 6.1k unique email addresses. The leaked data included extensive personal information such as physical appearance, income, education and IQ. A more comprehensive dataset was later provided to HIBP, containing usernames, IP addresses, private messages, phpBB password hashes and a total of 20k unique email addresses.

Check if you're affected
Verified
Dec 16, 20256.4M accounts
Email addressesGendersNamesPhone numbersPhysical addresses

In December 2025, data from France's Pass'Sport program was posted to a popular hacking forum. Initially misattributed to CAF (the French family allowance fund), the data contained 6.5M unique email addresses affecting 3.5M households. The data also included names, phone numbers, genders and physical addresses. The Ministry of Sports subsequently released a statement acknowledging the incident.

Check if you're affected

Think you're affected?

Check your email against 967 known breaches instantly. Find out what data has been exposed.

Check Your Email Now